Apache Content-Security-Policy .htaccess标头失败

在Firefox浏览器控制台中报告错误(Ctrl + Shift + J):

Content Security Policy: The page's settings blocked the loading of a resource at self (“default-src https://richardjaybrown.com”). Source: (function injected(eventName, injectedIn.... 

Firefox地址: https://richardjaybrown.com/ : https://richardjaybrown.com/

的.htaccess:

 Header set Vary: Accept-Encoding Header append Content-Security-Policy "default-src 'self'" 

注意:当网站地址在CSP中列出时也失败

环境:

Apache 2.4.9 Centos 7.4 virtuzzo WHM / cPanel 68.0.12 Firefox 56.0.2(Windows 8.1,华硕笔记本)